A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Uni
Subscribe
|
Cloud Key Gen2
Subscribe
Cloud Key Gen2 Plus
Subscribe
Ubiquiti Networks Unifi Dream Machine
Subscribe
Ubiquiti Networks Unifi Dream Machine Professional
Subscribe
Ubiquiti Networks Unifi Dream Machine Se
Subscribe
Unifi Dream Router
Subscribe
Unifi Os
Subscribe
Unifi Protect Network Video Recorder
Subscribe
Unifi Protect Network Video Recorder Professional
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32059 | A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 27 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-01-27T16:44:43.627Z
Reserved: 2023-03-15T00:00:00.000Z
Link: CVE-2023-28361
Updated: 2024-08-02T12:38:24.989Z
Status : Modified
Published: 2023-05-11T22:15:10.187
Modified: 2025-01-27T17:15:12.240
Link: CVE-2023-28361
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD